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TN THE CLAIMS: 

1 . (original) A network data processing system for identifying, locating, and 
deleting viruses, comprising: 

a local server; 

a plurality of client data processing systems; and 
a bait server, wherein 

the bait server monitors itself and, responsive to an attempt from an offending 
system within the network data processing system to access the bait server, the bait server 
broadcasts an indication that a virus attack is underway to all devices within the network 
data processing system, ignores all further access requests by the offending system until 
receiving an indication that the offending system has been disinfected, and directs the 
local server to disconnect the offending system from, the network data processing system. 

2. (original) The network data processing system as recited in claim 1 , wherein the 
address of the bait soever is not published to the plurality of client data processing 
systems. 

3. (original) The network data processing system as recited in claim 1, wherein the 
offending system includes more than one data processing system. 

4. (original) The network data processing system as recited in claim. 1, wherein the 
offending system includes the local server. 

5. (original) The network data processing system as recited in claim 1, wherein the 
offending system includes a client data processing system. 

6. (original) The network data processing system as recited in claim 1 , wherein the 
attempt from the offending system to access the bait server comprises an attempt to write 
to the bait server. 
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7. (original) The network data processing system as recited in claim 1 , wherein the 
virus is a worm. 

8. (original) The network data processing system as recited in claim 1 > wherein the 
virus is a Trojan horse. 

9. (original) The network data processing system as recited in claim 1, wherein the 
network data processing system is configured to, once the offending system has been 
disinfected of the client, allow the offending system to reconnect to the network data 
processing system. 

1 0. (original) A method for detecting the presence of a computer virus, the method 
comprising; 

receiving, at a bait server, a Tequest to perform a function on the bait server; 

identifying an offending system from which the request originated; 

alerting a local server that a virus attack is in progress and of the identity of the 

offending system; and 

directing the local server to disconnect the offending system from the network. 

1 L (original) The method as recited in claim 10, further comprising: 

prior to disconnecting the offending system, notifying the offending system that it 
is infected with a virus. 

12. (original) The method as recited in claim 10, further comprising: 
receiving a reconnect request from the offending system.; 

verifying that the offending system is disinfected and available to reconnect to the 
network; and 

reconnecting the offending system to the network. 



13. (cancelled) 
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14. (cancelled) 
15- (cancelled) 

16. (original) A method in a bait server for detecting the presence of a computer 
virus, the method comprising: 

monitoring a network for the presence of a computer virus; 

responsive to a determination that a virus is detected, determining the identity of 
an offending system within the network from which the virus entered the network; and 

directing the local server to disconnect the offending system from the network. 



17. (original) The method as recited in claim 16, further comprising: 

instructing all devices within the network to ignore all requests from, the offending 
system until the offending system has been disinfected and is available for network 
communication. 

I S. (currently amended) The method as recited in claim 16, further comprising: 

notifying a local server of the presence of the virus and the identity[[fy]] of the 
offending system. 

1 9. (original) The method as recited in claim 1 6, further comprising: 

responsive to an indication that the offending system has been disinfected and 
responsive to a reconnect request from the offending system, reconnecting the offending 
system to the network. 

20. (original) A computer program, product in a computer readable media for use in a 
data processing system for detecting the presence of a computer virus, the computer 
program product comprising; 

first instructions for receiving, at a bait server, a request to perfonn a function on 
the bait server; 

second instructions for identifying an offending system from, which the request 
originated; 
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third instructions for alerting a local server that a virus attack is in progress and 
the identity of the offending system; and 

fourth instructions for disconnecting the offending system from a network. 

21 . (original) The computer program product as recited in claim 20, further 
comprising: 

fifth instructions for, prior to disconnecting the offending system, notifying the 
offending system that it is infected with a virus. 

22. (original) The computer program product as recited in claim 20, further 
comprising: 

fifth instructions for receiving a reconnect request from, the offending system; 
sixth instructions for verifying that the offending system is disinfected and 
available to reconnect to the network; and 

seventh instructions for reconnecting the offending system to the network. 

23. (cancelled) 

24. (cancelled) 

25. (cancelled) 

26. (original) A computer program product in a computer readable media for use in a 
data processing system in a bait server for detecting the presence of a computer virus, the 
computer program product comprising: 

first instructions for monitoring a network for the presence of a computer virus; 

second instructions, responsive to a determination, that a virus is detected, for 
determining the identity of an offending system within the network from which the virus 
entered the network; and 

third instructions for disconnecting the offending system from the network. 
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27. (original) The computer program product as recited in claim 26, further 
comprising: 

fourth instructions for instructing all devices within the network to ignore all 
requests from the offending system until the offending system is reauthorized for network 
communi cation. 

28. (currently amended) The computer program product as recited in claim 26 ? 
further comprising: 

fourth instructi ons for noti fying a local server of the presence of the virus and the 
identity[[fy]] of the offending system. 

29. (original) The computer program product as recited in claim 26, further 
comprising: 

fourth instructions, responsive to an. indication that the offending system has been 
disinfected and responsive to a reconnect request from the offending system to the local 
server, for reconnecting the offending system to the network, 

30- (ori ginal) A system for detecting the presence of a computer virus, the system 
comprising; 

a receiver, at a bait server, which receives a request to perform a function on the 
bait server, 

an identifying unit which identifies an offending system from which the request 
originated; 

an virus alert unit which alerts a local server that a virus attack is in progress and 
the identity of the offending system; and 

disconnection unit which disconnects the offending system from a network. 

31 . (original) The system as recited in claim 30, flxrther comprising: 

a notification unit which, prior to disconnecting the offending system, notifies the 
offending system, that it is infected with a virus. 
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32. (original.) The system as recited in claim 30, further comprising: 

a reconnect request unit which receives a reconnect request from the offending 

system; 

a verification unit which verifies that the offending system is authorized to 
reconnect to the network; and 

a reconnecting unit which reconnects the offending system to the network, 

33. (cancelled) 

34. (cancelled) 

35. (cancelled) 

36. (original.) A system, in a bait server for detecting the presence of a computer 
virus, the system comprising: 

a monitoring unit which monitors a network for the presence of a computer virus; 

an identifier which, responsive to a determination that a virus is detected, 
deteimines the identity of an offending system within the network from which the vims 
entered the network; and 

a disconnection unit which disconnects the offending system from, the network. 

37. (original) The system as recited in claim 36, further comprising: 

a network protection unit which instructs all devices within the network to ignore 
all requests from the offending system until the offending system is reauthorized for 
network communication. 

38. (currently amended) The system as recited in claim 36, further comprising: 

a notification unit which notifies a local server of the presence of the virus and the 
identity[[fy]] of the offending system- 
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39. (original) The system as recited in claim 36, further comprising: 

a reconnection unit which, responsive to an indication that the offending system 
has been disinfected and responsive to a reconnect request from the offending system, 
reconnects the offending system to the network. 
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